Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.

Project Subscriptions

Vendors Products
Acrobat Subscribe
Acrobat Reader Subscribe
Solaris Subscribe
Rhel Extras Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://download.oracle.com/sunalerts/1019937.1.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html cve-icon cve-icon
http://osvdb.org/49520 cve-icon cve-icon
http://secunia.com/advisories/29773 cve-icon cve-icon
http://secunia.com/advisories/32700 cve-icon cve-icon
http://secunia.com/advisories/32872 cve-icon cve-icon
http://secunia.com/advisories/35163 cve-icon cve-icon
http://secunia.com/secunia_research/2008-14/ cve-icon cve-icon
http://securityreason.com/securityalert/4549 cve-icon cve-icon
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=800801 cve-icon cve-icon
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=909609 cve-icon cve-icon
http://www.adobe.com/support/security/bulletins/apsb08-19.html cve-icon cve-icon
http://www.coresecurity.com/content/adobe-reader-buffer-overflow cve-icon cve-icon
http://www.kb.cert.org/vuls/id/593409 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0974.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/498027/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/498032/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/498055/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/30035 cve-icon cve-icon
http://www.securityfocus.com/bid/32091 cve-icon cve-icon
http://www.securitytracker.com/id?1021140 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA08-309A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/3001 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/0098 cve-icon cve-icon
http://www.zerodayinitiative.com/advisories/ZDI-08-072/ cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-2992 cve-icon
https://www.cisa.gov/known-exploited-vulnerabilities-catalog cve-icon
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-2992 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-2992 cve-icon
https://www.exploit-db.com/exploits/6994 cve-icon cve-icon
https://www.exploit-db.com/exploits/7006 cve-icon cve-icon
History

Wed, 22 Oct 2025 01:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Mon, 10 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-03-03'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 23:15:00 +0000

Type Values Removed Values Added
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-22T00:05:55.512Z

Reserved: 2008-07-02T00:00:00.000Z

Link: CVE-2008-2992

cve-icon Vulnrichment

Updated: 2024-08-07T09:21:34.450Z

cve-icon NVD

Status : Deferred

Published: 2008-11-04T18:29:47.667

Modified: 2025-10-22T01:15:33.267

Link: CVE-2008-2992

cve-icon Redhat

Severity : Critical

Publid Date: 2008-11-04T00:00:00Z

Links: CVE-2008-2992 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses